Skype for Android has a major security flaw (Digital Trends)

Friday, April 15, 2011 6:01 AM

skype-large-logoIt was exclusive a hebdomad past that an Internet section firm peeked into Pandora‘s ambulatory app and determined that the consort is distribution “mass quantities” of individual info with ad agencies. Now Skype is being held under a microscope, particularly the company’s Android ambulatory app, and it seems that your stored personal data isn’t as innocuous as you’d belike same it to be.

After discovering that a leaked beta edition of the VoIP app was undefendable to an exploit that offers access to every individual data, Android Police tried the same tactic with the widely used Skype for Android, available since October 2010, and saw the same results. The site notes that the Skype Mobile for Verizon app appears to be unaffected, exclusive Skype for Android.

The theoretical info intend a little complicated, but essentially, Skype stores every individual data in a folder direction that user’s name. The database files contained within that folder hit incorrect permissions (simply, who/what crapper access them, and how), and furthermore, they aren’t encrypted. What every of this means is that these files, which contains everything from contacts and profile information to communication logs, crapper be both accessed and feature by anyone with bottom trouble.

The supply extends a taste deeper than that as well. If the supply were confined to meet what is detailed above, potential intruders would hit to hit the user’s Skype name. Still not abominably secure, but certainly more manageable. Unfortunately, there is also a artefact to vexer discover this information as well. Android Police notes that the big danger here is of a rogue developer releasing a tweaked edition of the app â€" think backwards to the past malware collapse on Android Market â€" that pulls discover and transmits clannish individual information.

The post concludes with whatever suggestions to Skype as to how this could be fixed. A after update reveals that the consort â€Å"is work this issue.â€


Source

0 comments:

Post a Comment